in.txt -> had all timestamps of users logon (100lines)
ex. 111111
222222
333333
out.txt -> had all timestamps of users logof (100lines)
ex. 111113
222225
333332
commands.txt -> timestamps anda the commands ofs de users (whatever)
ex.
111112
last >> last.txt
222223
other command
333333
another and another
i did a simple chinese
int in = 1 (lines of in.txt)
int out = 1 (lines of (out.txt)
int c = 1 (lines of commands.txt)
while ( in != end ){
printf(logon = in / logout = out);
while( c != end)
{
if ( c > in || c < out )
{
printf c+1;
c+2;
}
else
printf NO commands in this session;
c+2;
}
in++;
out++;
}
1285876440 :: 1285876440 .....................//is the same because is the current login
1285875600 :: 1285876140 ..................... //second line of in and out text
1285875611 last ...................................... //command used between the login
1285875780 history .................................. //command used between the login
1285871580 :: 1285871580 .....................//third line of in and out text
1285871040 :: 1285871100 ..................... //line 4 of in and out text
1285871080 nano .bashrc ......................... //command used between the login
1285870860 :: 1285870860 ..................... //line 5 of in and out text
1285870860 :: 1285876380 ..................... //line 6 of in and out text
1285871000 history .................................. //command used between the login
1285871325 sudo su .................................. //command used between the login
1285865100 :: 1285868160 ..................... //line 7 of in and out text
1285865300 history ................................. //command used between the login
#!/usr/bin/env ruby
# 1.9.1
f=File.readlines("history.txt")
f.each_with_index{|x,i| x.chomp!; f[i-1]<<" " << x and f=nil if (i+1)%2==0}
f.compact!
g=File.read("in.txt").split
h=File.read("out.txt").split
comb=g.zip(h)
final=[]
comb.each do |x|
final<<"#{x[0]} #{x[1]}"
f.each_with_index do |com,ind|
n,cmd=com.split
n=n.to_i
final<< com if n.to_i.between?(x[0].to_i,x[1].to_i)
end
end
puts final.uniq
$ ruby myscript.rb
1285876440 1285876440
1285875600 1285876140
1285875611 last
1285875780 history
1285871580 1285871580
1285871040 1285871100
1285871080 nano .bashrc
1285870860 1285870860
1285870860 1285876380
1285871000 history
1285871325 sudo su
1285865100 1285868160
1285865300 history
if you use delete $his{$} instead of undef $his{$} (recomendation of Perl docs) it will be better and processing will be lesser; because code will be as below:-